Three of the four active first-party sensitive-data endpoints in Pakistani government and telecom apps rely on domestic Pakistani infrastructure, identified via ASN and registry-level signals pointing to local administrative entities — placing identity credentials, location, and communication metadata within reach of Pakistani government administrative access.
From 2026-habib-empirical-study-backend — An Empirical Study of Backend Infrastructure in Leading Pakistani Mobile Apps
· Abstract
· 2026
· FOCI 2026
Implications
Assume data sent to Pakistani government app endpoints traverses domestically-controlled ASNs; circumvention tools should treat these endpoints as high-risk for state visibility even when the connection itself is TLS-encrypted.
Consider end-to-end encrypted overlays (not just transport-layer VPNs) for users running Pakistani government apps, since encryption in transit does not protect data once it reaches a domestically-administered server.